Secret Sharing Document System for Secure Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems face challenges in securing data transmission over public networks, as highly secure systems often require extensive user knowledge and are vulnerable to attacks, while easier-to-use systems are less secure.

Innovation Solution

A document sharing system that employs secret-sharing processes and nested secret sharing to distribute encryption keys among approval groups, ensuring secure operations and logging, allowing for easy user interface management without password access, and enabling secure document sharing, retrieval, and recovery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If highly secure encryption systems are used to protect communications and stored data, then security against unauthorized disclosure is improved, but user interface complexity and difficulty of operation increase

Engineering Contradiction:
ImprovesecurityVSAvoiduser interface complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The encryption key is divided into multiple shares using secret sharing schemes, where no single entity holds the complete key. This segmentation allows the system to maintain high security while enabling distributed key management through automated processes, reducing the operational burden on users.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces automated key management intermediaries that handle cryptographic operations, key distribution, and access control. These intermediaries mediate between users and the complex security infrastructure, providing simple interfaces while maintaining strong security through automated enforcement of access policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If automated operations are performed on encryption keys to simplify user interaction, then ease of operation is improved, but security vulnerabilities may be introduced through compromised operations

Engineering Contradiction:
Improveautomated key managementVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system preemptively protects against security vulnerabilities by implementing approval workflows that require multiple authorized parties to consent before performing operations on encryption keys. This preliminary anti-action prevents any single compromised operation from jeopardizing security, as the multi-party approval mechanism ensures that malicious or erroneous operations are detected and blocked before execution.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If encryption keys are distributed among multiple parties using secret sharing, then security against single-point compromise is improved, but system complexity increases

Engineering Contradiction:
Improveresistance to single-point compromiseVSAvoidkey distribution system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements a universal key management platform that handles multiple cryptographic operations, secret sharing schemes, and access control mechanisms through a single integrated infrastructure. This multi-functionality reduces overall system complexity by consolidating what would otherwise require separate systems for key generation, distribution, management, and revocation into one cohesive platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If approval workflows are implemented for key operations to prevent unauthorized access, then security is improved, but operation time and productivity decrease

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidkey operation speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary setup of approval workflows and access policies during system initialization or key creation phases. By pre-configuring approval requirements and authorized parties, the system eliminates the need for real-time complex negotiations during key operations. The pre-established rules enable automated decision-making that maintains security while significantly reducing operational delays.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9954684B2Secure sharing
Publication Date: 2018.04.24 PREVEIL LLC
  • US9954684B2 patent drawing
  • US9954684B2 patent drawing
  • US9954684B2 patent drawing

AI summary

Among other things, at a central server, management of a document sharing process includes uploading from client devices through a communication network, storing at the server, and downloading to client devices through the communication network documents that are shared between users of the client devices. Encryption keys are used to protect features of the documents from unauthorized or unintended disclosure. Operations are performed on encryption keys or encrypted data as a result of which protection of features of the documents from unauthorized or unintended disclosure may be compromised. A determination is made whether performance of a given one of the operations on any of the encryption keys or encrypted data meets predefined conditions for approval by members of an approval group. Performance of the operation on the encryption key or encrypted data is controlled based on a result of the determination.